UAE Information Assurance Standard, Version 2. Published September 2025.

UAE IA Standard v2 readiness for government entities and critical operators

The UAE Information Assurance Standard is the national baseline for government entities and critical infrastructure operators, and it flows by contract to their suppliers. Version 2, published by the Cyber Security Council in September 2025, replaces the older standard: 15 control families aligned to ISO 27001:2022, with cloud, IoT, AI and post-quantum topics added. It is also the reference the National Cyber Accreditation Program draws on. We map it to your environment and show you where you stand.

Get your IA Standard v2 readiness picture

Protect government information and critical services

The national baseline for government information security.

The UAE Information Assurance Standard is the national baseline for federal ministries, government entities and critical service providers, and it reaches their suppliers through contract. Version 2 was published by the Cyber Security Council in September 2025 and replaces the older standard, reorganising it into 15 control families aligned to ISO 27001:2022 and adding cloud, IoT, AI and post-quantum topics. TDRA operates aeCERT, the national CERT that designated entities report incidents to. The regulation prescribes self-assessment and reporting at the level your designation requires. It is also the reference the National Cyber Accreditation Program draws on, so suppliers to government meet it through the baseline they are asked to show.

0
IA v2 controls
0
IA v2 control families
0
IA v2 sub-controls

Government information security is mandatory. Compliance becomes manageable with automation.

Establish Information Assurance Governance

Establish Information Assurance Governance

The IA Standard requires formal governance: information security policies aligned with the standard, organizational structures with defined roles and responsibilities, senior management oversight, and regular policy reviews. Many government entities lack governance frameworks meeting the IA Standard requirements. Governance failures leave entities unable to manage information security systematically and unable to demonstrate compliance with the standard. We map the governance requirements to what you have, assess whether the policies, roles and oversight are documented and current, assign remediation, and keep the documentation assessors examine.

Government governance. Standard-aligned policies. Management oversight.

Implement Information Classification and Handling

Implement Information Classification and Handling

The IA Standard mandates systematic information classification: asset inventory, classification levels (public, internal, confidential, secret), handling requirements, labeling standards, and disposal procedures. Government information includes citizen data, national security information, and operational systems. Classification failures expose sensitive information to unauthorized access and compromise national security. We assess your classification scheme and asset inventory against the requirement, show where handling and labelling break down in practice, and keep the classification records the regulation expects. Applying the labels and handling the information is work that happens in your systems and by your people.

Asset inventory. Classification levels. Handling procedures.

Implement Access Control and Identity Management

Implement Access Control and Identity Management

The IA Standard requires complete access controls: user registration and de-registration, authentication mechanisms, authorization management, privileged access controls, remote access security, and access monitoring. Government systems contain sensitive citizen information and national security data. Access control failures enable unauthorized disclosure and compromise government operations. We assess your access controls against the requirement: how authentication is configured, how privilege is granted and reviewed, whether access is removed on the day someone leaves, and whether the logs would show it. We do not enforce your authentication or administer your privileged accounts; those run in your identity systems. We report what they show and keep the documentation assessors review.

User authentication. Authorization management. Access monitoring.

Implement Cryptographic Controls

Implement Cryptographic Controls

The IA Standard sets cryptographic requirements: encryption for data at rest and in transit, key management procedures, approved algorithms, digital signatures and secure communications. Government information requires protection from interception and tampering, and cryptographic gaps expose it. We assess your cryptographic controls against the requirement, record where key management sits and who owns it, and track the gaps to closure. The cryptography itself runs in your systems; we do not operate it or hold your keys.

Approved algorithms. Key management. Secure communications.

Establish Information Security Incident Management

Establish Information Security Incident Management

The IA Standard requires incident response capabilities: detection mechanisms, reporting procedures, analysis and triage, containment and eradication, and recovery. Designated entities report incidents to aeCERT, the national CERT operated by TDRA, and that duty sits with the entity. We help you write the procedure before you need it, rehearse it against the clock it has to meet, and keep the incident records the standard expects. We do not speak to the national authorities on your behalf.

Incident detection. Reporting to aeCERT. Recovery procedures.

Prepare for Information Assurance assessment

Prepare for Information Assurance assessment

The Information Assurance Regulation prescribes self-assessment and reporting against the standard, at the level your designation requires, across governance, classification, access control, cryptography, network and system security, incident management and continuity. What is assessed is technical implementation, policy, documentation and operational effectiveness. We keep that record current rather than assembled the week before, so the assessment reads as verification of what you already run.

Always assessment-ready. Complete documentation. Current evidence.

Why Government Entities Choose This Path

From information security gaps to a defensible position against the standard.

Organizations working with us:

Stay assessment-ready

Evidence kept current rather than assembled the week before, so an assessment verifies what you already run.

Protect Government Information

The standard's controls protect classified information, citizen data and operational systems from unauthorized access and disclosure.

Put the governance in place

Formal governance gives systematic information security management that meets the standard across the whole entity.

Classify Information Assets

Systematic classification ensures proper handling of government information at all classification levels from public to secret.

Control Access

Complete access controls prevent unauthorized access to sensitive government systems and classified information.

Secure Communications

Cryptographic controls assessed against the standard, so government communications keep their confidentiality and integrity.

Built for UAE IA Standard v2 readiness across government and critical operators.

Cover the UAE IA Standard v2 control families

Version 2 reorganises the standard into 15 control families. The platform maps them to your environment.

The UAE Information Assurance Standard Version 2 sets requirements across governance, information classification and handling, access control and identity management, cryptographic controls, network security, system acquisition and development, incident management and business continuity, with cloud, IoT, AI and post-quantum topics added in this version. The platform maps those requirements to your environment, assesses implementation, manages evidence and remediation, and validates selected technical controls through supported telemetry.

15 families. 134 controls. 449 sub-controls.

UAE IA Standard v2 control areas

What the standard requires of the entity

Information security governance and organization
Information classification and handling procedures
Access control and identity management systems
Cryptographic controls and key management requirements
Network security architecture and controls
System acquisition, development, and maintenance
Information security incident management
Business continuity management and disaster recovery
Physical and environmental security measures
Human resources security and awareness training
Cloud, IoT and AI control areas added in Version 2
Self-assessment and evidence records for the reporting the regulation prescribes